<!DOCTYPE html><html lang="zh-CN" data-theme="light"><head><meta charset="UTF-8"><meta http-equiv="X-UA-Compatible" content="IE=edge"><meta name="viewport" content="width=device-width, initial-scale=1.0,viewport-fit=cover"><title>iptables | 惰 立</title><meta name="author" content="惰 立"><meta name="copyright" content="惰 立"><meta name="format-detection" content="telephone=no"><meta name="theme-color" content="#ffffff"><meta name="description" content="iptables入门">
<meta property="og:type" content="article">
<meta property="og:title" content="iptables">
<meta property="og:url" content="https://duolili.duolili.top/2023/11/23/iptables/index.html">
<meta property="og:site_name" content="惰 立">
<meta property="og:description" content="iptables入门">
<meta property="og:locale" content="zh_CN">
<meta property="og:image" content="https://cdn.jsdelivr.net/gh/duoli-hub/cdn/source/img/cover/4.png">
<meta property="article:published_time" content="2023-11-23T08:44:45.000Z">
<meta property="article:modified_time" content="2023-11-23T09:13:54.532Z">
<meta property="article:author" content="惰 立">
<meta property="article:tag" content="Linux">
<meta property="article:tag" content="运维">
<meta property="article:tag" content="iptable">
<meta name="twitter:card" content="summary">
<meta name="twitter:image" content="https://cdn.jsdelivr.net/gh/duoli-hub/cdn/source/img/cover/4.png"><link rel="shortcut icon" href="/img/favicon.png"><link rel="canonical" href="https://duolili.duolili.top/2023/11/23/iptables/index.html"><link rel="preconnect" href="//cdn.jsdelivr.net"/><link rel="preconnect" href="//fonts.googleapis.com" crossorigin=""/><link rel="preconnect" href="//busuanzi.ibruce.info"/><link rel="stylesheet" href="/css/index.css"><link rel="stylesheet" href="https://cdn.jsdelivr.net/npm/@fortawesome/fontawesome-free/css/all.min.css" media="print" onload="this.media='all'"><link rel="stylesheet" href="https://cdn.jsdelivr.net/npm/@fancyapps/ui/dist/fancybox/fancybox.min.css" media="print" onload="this.media='all'"><link rel="stylesheet" href="https://fonts.googleapis.com/css?family=Titillium+Web&amp;display=swap" media="print" onload="this.media='all'"><script>const GLOBAL_CONFIG = {
  root: '/',
  algolia: undefined,
  localSearch: undefined,
  translate: undefined,
  noticeOutdate: undefined,
  highlight: {"plugin":"highlighjs","highlightCopy":true,"highlightLang":true,"highlightHeightLimit":false},
  copy: {
    success: '复制成功',
    error: '复制错误',
    noSupport: '浏览器不支持'
  },
  relativeDate: {
    homepage: false,
    post: false
  },
  runtime: '天',
  dateSuffix: {
    just: '刚刚',
    min: '分钟前',
    hour: '小时前',
    day: '天前',
    month: '个月前'
  },
  copyright: {"limitCount":50,"languages":{"author":"作者: 惰 立","link":"链接: ","source":"来源: 惰 立","info":"著作权归作者所有。商业转载请联系作者获得授权，非商业转载请注明出处。"}},
  lightbox: 'fancybox',
  Snackbar: undefined,
  infinitegrid: {
    js: 'https://cdn.jsdelivr.net/npm/@egjs/infinitegrid/dist/infinitegrid.min.js',
    buttonText: '加载更多'
  },
  isPhotoFigcaption: false,
  islazyload: false,
  isAnchor: false,
  percent: {
    toc: true,
    rightside: true,
  },
  autoDarkmode: false
}</script><script id="config-diff">var GLOBAL_CONFIG_SITE = {
  title: 'iptables',
  isPost: true,
  isHome: false,
  isHighlightShrink: false,
  isToc: true,
  postUpdate: '2023-11-23 17:13:54'
}</script><script>(win=>{
      win.saveToLocal = {
        set: (key, value, ttl) => {
          if (ttl === 0) return
          const now = Date.now()
          const expiry = now + ttl * 86400000
          const item = {
            value,
            expiry
          }
          localStorage.setItem(key, JSON.stringify(item))
        },
      
        get: key => {
          const itemStr = localStorage.getItem(key)
      
          if (!itemStr) {
            return undefined
          }
          const item = JSON.parse(itemStr)
          const now = Date.now()
      
          if (now > item.expiry) {
            localStorage.removeItem(key)
            return undefined
          }
          return item.value
        }
      }
    
      win.getScript = (url, attr = {}) => new Promise((resolve, reject) => {
        const script = document.createElement('script')
        script.src = url
        script.async = true
        script.onerror = reject
        script.onload = script.onreadystatechange = function() {
          const loadState = this.readyState
          if (loadState && loadState !== 'loaded' && loadState !== 'complete') return
          script.onload = script.onreadystatechange = null
          resolve()
        }

        Object.keys(attr).forEach(key => {
          script.setAttribute(key, attr[key])
        })

        document.head.appendChild(script)
      })
    
      win.getCSS = (url, id = false) => new Promise((resolve, reject) => {
        const link = document.createElement('link')
        link.rel = 'stylesheet'
        link.href = url
        if (id) link.id = id
        link.onerror = reject
        link.onload = link.onreadystatechange = function() {
          const loadState = this.readyState
          if (loadState && loadState !== 'loaded' && loadState !== 'complete') return
          link.onload = link.onreadystatechange = null
          resolve()
        }
        document.head.appendChild(link)
      })
    
      win.activateDarkMode = () => {
        document.documentElement.setAttribute('data-theme', 'dark')
        if (document.querySelector('meta[name="theme-color"]') !== null) {
          document.querySelector('meta[name="theme-color"]').setAttribute('content', '#0d0d0d')
        }
      }
      win.activateLightMode = () => {
        document.documentElement.setAttribute('data-theme', 'light')
        if (document.querySelector('meta[name="theme-color"]') !== null) {
          document.querySelector('meta[name="theme-color"]').setAttribute('content', '#ffffff')
        }
      }
      const t = saveToLocal.get('theme')
    
        if (t === 'dark') activateDarkMode()
        else if (t === 'light') activateLightMode()
      
      const asideStatus = saveToLocal.get('aside-status')
      if (asideStatus !== undefined) {
        if (asideStatus === 'hide') {
          document.documentElement.classList.add('hide-aside')
        } else {
          document.documentElement.classList.remove('hide-aside')
        }
      }
    
      const detectApple = () => {
        if(/iPad|iPhone|iPod|Macintosh/.test(navigator.userAgent)){
          document.documentElement.classList.add('apple')
        }
      }
      detectApple()
    })(window)</script><meta name="generator" content="Hexo 7.0.0"></head><body><div id="web_bg"></div><div id="sidebar"><div id="menu-mask"></div><div id="sidebar-menus"><div class="avatar-img is-center"><img src="/img/tou.jpeg" onerror="onerror=null;src='/img/friend_404.gif'" alt="avatar"/></div><div class="sidebar-site-data site-data is-center"><a href="/archives/"><div class="headline">文章</div><div class="length-num">6</div></a><a href="/tags/"><div class="headline">标签</div><div class="length-num">7</div></a><a href="/categories/"><div class="headline">分类</div><div class="length-num">2</div></a></div><hr class="custom-hr"/><div class="menus_items"><div class="menus_item"><a class="site-page" href="/"><i class="fa-fw fas fa-home"></i><span> 主页</span></a></div><div class="menus_item"><a class="site-page" href="/archives/"><i class="fa-fw fas fa-archive"></i><span> 归档</span></a></div><div class="menus_item"><a class="site-page" href="/tags/"><i class="fa-fw fas fa-tags"></i><span> 标签</span></a></div><div class="menus_item"><a class="site-page" href="/categories/"><i class="fa-fw fas fa-folder-open"></i><span> 分类</span></a></div><div class="menus_item"><a class="site-page group" href="javascript:void(0);"><i class="fa-fw fas fa-list"></i><span> 媒体</span><i class="fas fa-chevron-down"></i></a><ul class="menus_item_child"><li><a class="site-page child" href="/music/"><i class="fa-fw fas fa-music"></i><span> Music</span></a></li><li><a class="site-page child" href="/movies/"><i class="fa-fw fas fa-video"></i><span> Movie</span></a></li></ul></div><div class="menus_item"><a class="site-page" href="/link/"><i class="fa-fw fas fa-link"></i><span> 链接</span></a></div><div class="menus_item"><a class="site-page" href="/about/"><i class="fa-fw fas fa-heart"></i><span> 关于</span></a></div></div></div></div><div class="post" id="body-wrap"><header class="post-bg fixed" id="page-header" style="background-image: url('https://cdn.jsdelivr.net/gh/duoli-hub/cdn/source/img/cover/4.png')"><nav id="nav"><span id="blog-info"><a href="/" title="惰 立"><span class="site-name">惰 立</span></a></span><div id="menus"><div class="menus_items"><div class="menus_item"><a class="site-page" href="/"><i class="fa-fw fas fa-home"></i><span> 主页</span></a></div><div class="menus_item"><a class="site-page" href="/archives/"><i class="fa-fw fas fa-archive"></i><span> 归档</span></a></div><div class="menus_item"><a class="site-page" href="/tags/"><i class="fa-fw fas fa-tags"></i><span> 标签</span></a></div><div class="menus_item"><a class="site-page" href="/categories/"><i class="fa-fw fas fa-folder-open"></i><span> 分类</span></a></div><div class="menus_item"><a class="site-page group" href="javascript:void(0);"><i class="fa-fw fas fa-list"></i><span> 媒体</span><i class="fas fa-chevron-down"></i></a><ul class="menus_item_child"><li><a class="site-page child" href="/music/"><i class="fa-fw fas fa-music"></i><span> Music</span></a></li><li><a class="site-page child" href="/movies/"><i class="fa-fw fas fa-video"></i><span> Movie</span></a></li></ul></div><div class="menus_item"><a class="site-page" href="/link/"><i class="fa-fw fas fa-link"></i><span> 链接</span></a></div><div class="menus_item"><a class="site-page" href="/about/"><i class="fa-fw fas fa-heart"></i><span> 关于</span></a></div></div><div id="toggle-menu"><a class="site-page" href="javascript:void(0);"><i class="fas fa-bars fa-fw"></i></a></div></div></nav><div id="post-info"><h1 class="post-title">iptables</h1><div id="post-meta"><div class="meta-firstline"><span class="post-meta-date"><i class="far fa-calendar-alt fa-fw post-meta-icon"></i><span class="post-meta-label">发表于</span><time class="post-meta-date-created" datetime="2023-11-23T08:44:45.000Z" title="发表于 2023-11-23 16:44:45">2023-11-23</time><span class="post-meta-separator">|</span><i class="fas fa-history fa-fw post-meta-icon"></i><span class="post-meta-label">更新于</span><time class="post-meta-date-updated" datetime="2023-11-23T09:13:54.532Z" title="更新于 2023-11-23 17:13:54">2023-11-23</time></span><span class="post-meta-categories"><span class="post-meta-separator">|</span><i class="fas fa-inbox fa-fw post-meta-icon"></i><a class="post-meta-categories" href="/categories/%E8%BF%90%E7%BB%B4/">运维</a><i class="fas fa-angle-right post-meta-separator"></i><i class="fas fa-inbox fa-fw post-meta-icon"></i><a class="post-meta-categories" href="/categories/%E8%BF%90%E7%BB%B4/Linux/">Linux</a></span></div><div class="meta-secondline"><span class="post-meta-separator">|</span><span class="post-meta-wordcount"><i class="far fa-file-word fa-fw post-meta-icon"></i><span class="post-meta-label">字数总计:</span><span class="word-count">1.5k</span><span class="post-meta-separator">|</span><i class="far fa-clock fa-fw post-meta-icon"></i><span class="post-meta-label">阅读时长:</span><span>5分钟</span></span><span class="post-meta-separator">|</span><span class="post-meta-pv-cv" id="" data-flag-title="iptables"><i class="far fa-eye fa-fw post-meta-icon"></i><span class="post-meta-label">阅读量:</span><span id="busuanzi_value_page_pv"><i class="fa-solid fa-spinner fa-spin"></i></span></span></div></div></div></header><main class="layout" id="content-inner"><div id="post"><article class="post-content" id="article-container"><h2 id="四表五链"><a href="#四表五链" class="headerlink" title="四表五链"></a>四表五链</h2><ul>
<li>四表</li>
</ul>
<ol>
<li>FILTER：进行数据包的过滤性处理<ol>
<li>INPUT链：对需要进入的流量数据进行规则匹配（外部–&gt;本机）</li>
<li>OUTPUT链：对需要出去的流量进行规则匹配（本机–&gt;外部）</li>
<li>FORWARD：对流经的流量数据进行规则匹配（外部1–&gt;本机转发–&gt;外部2）</li>
</ol>
</li>
<li>NAT表：对数据包中的地址信息进行转换<ol>
<li>postrouting：对某数据处理之后要做的事情即对经过路由之后的数据的处理性操作，实现内部共享上网功能</li>
<li>prerouting：对某数据处理之前要做的事情即对经过路由之前的数据的处理性操作，实现外网转发内网功能</li>
</ol>
</li>
<li>MANGLE表：对数据包信息进行标记修改操作</li>
<li>RAW表：将数据包中的信息进行拆解</li>
</ol>
<h2 id="安装防火墙服务端"><a href="#安装防火墙服务端" class="headerlink" title="安装防火墙服务端"></a>安装防火墙服务端</h2><figure class="highlight shell"><table><tr><td class="gutter"><pre><span class="line">1</span><br></pre></td><td class="code"><pre><span class="line">yum install iptables-services -y</span><br></pre></td></tr></table></figure>

<h2 id="启动"><a href="#启动" class="headerlink" title="启动"></a>启动</h2><figure class="highlight sh"><table><tr><td class="gutter"><pre><span class="line">1</span><br></pre></td><td class="code"><pre><span class="line">systemctl start iptables</span><br></pre></td></tr></table></figure>

<h2 id="查看规则"><a href="#查看规则" class="headerlink" title="查看规则"></a>查看规则</h2><figure class="highlight shell"><table><tr><td class="gutter"><pre><span class="line">1</span><br></pre></td><td class="code"><pre><span class="line">iptables -nL</span><br></pre></td></tr></table></figure>

<h2 id="防火墙初始化规则"><a href="#防火墙初始化规则" class="headerlink" title="防火墙初始化规则"></a>防火墙初始化规则</h2><figure class="highlight shell"><table><tr><td class="gutter"><pre><span class="line">1</span><br><span class="line">2</span><br><span class="line">3</span><br><span class="line">4</span><br><span class="line">5</span><br><span class="line">6</span><br></pre></td><td class="code"><pre><span class="line"><span class="meta prompt_"># </span><span class="language-bash">清空所有链上的规则</span></span><br><span class="line">iptables -F</span><br><span class="line"><span class="meta prompt_"># </span><span class="language-bash">清空所有计数器信息(计数器：帮助排查规则不通的问题的)</span></span><br><span class="line">iptabled -Z</span><br><span class="line"><span class="meta prompt_"># </span><span class="language-bash">清空用户自定义链的所有规则</span></span><br><span class="line">iptables -X</span><br></pre></td></tr></table></figure>

<h2 id="查看防火墙规则"><a href="#查看防火墙规则" class="headerlink" title="查看防火墙规则"></a>查看防火墙规则</h2><blockquote>
<p>-L	通过列表显示当前防火墙的规则信息</p>
<p>-n	默认按照ip与端口显示，不解析协议名称</p>
<p>-v	详细显示规则信息</p>
<p>–line-numbers	按照序号显示规则</p>
<p>-t	指定显示规则的表（不指定时，默认显示FILTER表的规则）</p>
</blockquote>
<figure class="highlight shell"><table><tr><td class="gutter"><pre><span class="line">1</span><br><span class="line">2</span><br></pre></td><td class="code"><pre><span class="line"><span class="meta prompt_"># </span><span class="language-bash">查看nat表的所有规则</span></span><br><span class="line">iptables -t nat -nL</span><br></pre></td></tr></table></figure>

<h2 id="基于filter表规则配置"><a href="#基于filter表规则配置" class="headerlink" title="基于filter表规则配置"></a>基于filter表规则配置</h2><blockquote>
<pre><code>            -t			指定表，不指定时默认为filter表
            -A			在指定链添加规则，默认添加至末尾
            -I			在指定链中插入规则，默认添加至首行
            -p			指定协议：TCP、UDP、ICMP、ARP、HTTP、FTP、DNS
            --dport		指定目的端口
            --sport		指定来源端口
            -s			指定来源地址信息
            -i			指定接收流向的网卡设备
            -o			指定出口流量的网卡设备
            -j			指定规则策略：DROP(丢弃包)、ACCEPT、REJECT(拒绝)
            !			取反
</code></pre>
</blockquote>
<ul>
<li>阻止所有用户不能访问ssh远程服务</li>
</ul>
<figure class="highlight shell"><table><tr><td class="gutter"><pre><span class="line">1</span><br><span class="line">2</span><br></pre></td><td class="code"><pre><span class="line"><span class="meta prompt_"># </span><span class="language-bash">操作filter表</span></span><br><span class="line">iptables -A INPUT -p tcp --dport 22 -j DROP</span><br></pre></td></tr></table></figure>

<ul>
<li>阻止windows远程连接到虚拟机，允许其他网段连接</li>
</ul>
<figure class="highlight shell"><table><tr><td class="gutter"><pre><span class="line">1</span><br><span class="line">2</span><br></pre></td><td class="code"><pre><span class="line"><span class="meta prompt_"># </span><span class="language-bash">操作filter表</span></span><br><span class="line">iptables -A INPUT -p tcp -s 10.0.0.1 --dport 22 -j DROP</span><br></pre></td></tr></table></figure>

<ul>
<li>只允许windows连接，其他网段全不允许</li>
</ul>
<figure class="highlight shell"><table><tr><td class="gutter"><pre><span class="line">1</span><br><span class="line">2</span><br><span class="line">3</span><br><span class="line">4</span><br><span class="line">5</span><br></pre></td><td class="code"><pre><span class="line"><span class="meta prompt_"># </span><span class="language-bash">方法一</span></span><br><span class="line">iptables -A INPUT -p tcp -s 10.0.0.1 --dport 22 -j ACCEPT</span><br><span class="line">iptables -A INPUT -p tcp -s 0.0.0.0/0 --dport 22 -j DROP</span><br><span class="line"><span class="meta prompt_"># </span><span class="language-bash">方法二</span></span><br><span class="line">iptables -A INPUT -p tcp ! -s 10.0.0.1 --dport 22 -j DROP</span><br></pre></td></tr></table></figure>

<ul>
<li>只允许通过内网访问80端口，不允许通过外网访问80端口</li>
</ul>
<figure class="highlight shell"><table><tr><td class="gutter"><pre><span class="line">1</span><br><span class="line">2</span><br><span class="line">3</span><br></pre></td><td class="code"><pre><span class="line"><span class="meta prompt_"># </span><span class="language-bash">两张网卡的情况下</span></span><br><span class="line">iptables -A INPUT -p tcp -i eth1 --dport 80 -j ACCEPT</span><br><span class="line">iptables -A INPUT -p tcp -i eth0 --dport 80 -j DROP</span><br></pre></td></tr></table></figure>

<h3 id="定义防火墙规则顺序"><a href="#定义防火墙规则顺序" class="headerlink" title="定义防火墙规则顺序"></a>定义防火墙规则顺序</h3><blockquote>
<p>-I			在指定链的某个规则前插入规则</p>
</blockquote>
<ul>
<li>凡是访问本机80端口，都放行，其他端口都拒绝</li>
</ul>
<figure class="highlight shell"><table><tr><td class="gutter"><pre><span class="line">1</span><br><span class="line">2</span><br><span class="line">3</span><br><span class="line">4</span><br><span class="line">5</span><br><span class="line">6</span><br><span class="line">7</span><br><span class="line">8</span><br></pre></td><td class="code"><pre><span class="line"><span class="meta prompt_"># </span><span class="language-bash">放行所有本地windows请求</span></span><br><span class="line">iptables -A INPUT -p tcp -s 10.0.0.1 -j ACCEPT</span><br><span class="line"><span class="meta prompt_"># </span><span class="language-bash">拒绝所有tcp请求</span></span><br><span class="line">iptables -A INPUT -p tcp -j DROP</span><br><span class="line"><span class="meta prompt_"># </span><span class="language-bash">查看规则序号</span></span><br><span class="line">iptables -nL --line-numbers</span><br><span class="line"><span class="meta prompt_"># </span><span class="language-bash">在第二条规则前插入一条规则：放通所有请求80端口的请求</span></span><br><span class="line">iptables -I INPUT 2 -p tcp --dport 80 -j ACCEPT</span><br></pre></td></tr></table></figure>

<h3 id="基于现有规则去修改"><a href="#基于现有规则去修改" class="headerlink" title="基于现有规则去修改"></a>基于现有规则去修改</h3><blockquote>
<p>-R		修改规则</p>
</blockquote>
<ul>
<li>修改第二条规则：将原放通80端口修改为放通22端口</li>
</ul>
<figure class="highlight shell"><table><tr><td class="gutter"><pre><span class="line">1</span><br></pre></td><td class="code"><pre><span class="line">iptables -R INPUT 2 -p tcp --dport 22 -j ACCEPT</span><br></pre></td></tr></table></figure>

<h3 id="同时放行某范围内的所有端口"><a href="#同时放行某范围内的所有端口" class="headerlink" title="同时放行某范围内的所有端口"></a>同时放行某范围内的所有端口</h3><figure class="highlight shell"><table><tr><td class="gutter"><pre><span class="line">1</span><br></pre></td><td class="code"><pre><span class="line">iptables -R INPUT 2 -p tcp --dport 22:80 -j ACCEPT</span><br></pre></td></tr></table></figure>

<h3 id="指定开放某几个端口"><a href="#指定开放某几个端口" class="headerlink" title="指定开放某几个端口"></a>指定开放某几个端口</h3><blockquote>
<p>-m		指定某些扩展模块，实现某些功能</p>
<p>multiport		模块：用于指定多个端口进行规则匹配</p>
<p>limit			模块：设定单位时间内访问多少个ip（实现防护恶意攻击、恶意点击行为）</p>
<p>–limit-burst		模块：设定阈值，到达第几个开始触发规则</p>
</blockquote>
<figure class="highlight shell"><table><tr><td class="gutter"><pre><span class="line">1</span><br><span class="line">2</span><br></pre></td><td class="code"><pre><span class="line"><span class="meta prompt_"># </span><span class="language-bash">同时放通22、80、443端口</span></span><br><span class="line">iptables -R INPUT 2 -p tcp -m multiport --dport 22,80,443 -j ACCEPT</span><br></pre></td></tr></table></figure>

<h3 id="禁用ping"><a href="#禁用ping" class="headerlink" title="禁用ping"></a>禁用ping</h3><p>ping依赖的是icmp协议</p>
<p>icmp基于ping-pong，ping是icmp其中的一个请求类型：0 回复	8 请求</p>
<figure class="highlight shell"><table><tr><td class="gutter"><pre><span class="line">1</span><br><span class="line">2</span><br><span class="line">3</span><br><span class="line">4</span><br></pre></td><td class="code"><pre><span class="line"><span class="meta prompt_"># </span><span class="language-bash">方法一：基于INPUT链</span></span><br><span class="line">iptables -A INPUT -p icmp --icmp-type 8 -j DROP</span><br><span class="line"><span class="meta prompt_"># </span><span class="language-bash">方法二：基于OUTPUT链</span></span><br><span class="line">iptables -A OUTPUT -p icmp --icmp-type 0 -j DROP</span><br></pre></td></tr></table></figure>

<h3 id="限制每分钟最多可以ping6次，从第十次开始触发"><a href="#限制每分钟最多可以ping6次，从第十次开始触发" class="headerlink" title="限制每分钟最多可以ping6次，从第十次开始触发"></a>限制每分钟最多可以ping6次，从第十次开始触发</h3><figure class="highlight shell"><table><tr><td class="gutter"><pre><span class="line">1</span><br><span class="line">2</span><br></pre></td><td class="code"><pre><span class="line">iptables -A OUTPUT -p icmp --icmp-type 0 -j DROP</span><br><span class="line">iptables -I OUTPUT 1 -p icmp --icmp-type 0 -m limit 6/min --limit-burst 10 -j ACCEPT</span><br></pre></td></tr></table></figure>

<h3 id="删除规则"><a href="#删除规则" class="headerlink" title="删除规则"></a>删除规则</h3><blockquote>
<p>-D</p>
</blockquote>
<figure class="highlight shell"><table><tr><td class="gutter"><pre><span class="line">1</span><br><span class="line">2</span><br><span class="line">3</span><br><span class="line">4</span><br></pre></td><td class="code"><pre><span class="line"><span class="meta prompt_"># </span><span class="language-bash">方法一</span></span><br><span class="line">iptables -D OUTPUT -p icmp --icmp-type 0 -j DROP</span><br><span class="line"><span class="meta prompt_"># </span><span class="language-bash">方法二：基于序号删除</span></span><br><span class="line">iptables -D INPUT 2</span><br></pre></td></tr></table></figure>

<h3 id="修改默认规则"><a href="#修改默认规则" class="headerlink" title="修改默认规则"></a>修改默认规则</h3><p>默认规则放通全部</p>
<p>修改默认规则拒绝全部</p>
<figure class="highlight shell"><table><tr><td class="gutter"><pre><span class="line">1</span><br></pre></td><td class="code"><pre><span class="line">iptables -P INPUT DROP</span><br></pre></td></tr></table></figure>

<h2 id="基于nat表规则配置"><a href="#基于nat表规则配置" class="headerlink" title="基于nat表规则配置"></a>基于nat表规则配置</h2><p><code>POSTROUTING</code>：地址或端口映射。先进行路由，后进行地址转换</p>
<p><code>PREROUTING</code>：地址或端口映射。先进行地址转换，后进行路由转发</p>
<h3 id="NAT实现内部网络共享上网功能"><a href="#NAT实现内部网络共享上网功能" class="headerlink" title="NAT实现内部网络共享上网功能"></a>NAT实现内部网络共享上网功能</h3><p>实现demo2通过demo1的ens33网卡访问百度</p>
<ul>
<li><p>环境</p>
<p>demo1：</p>
<p>​	ens33：10.0.0.31	可通外网</p>
<p>​	ens34：192.168.10.10	内网</p>
<p>demo2：</p>
<p>​	ens34:192.168.10.11	内网</p>
</li>
<li><p>操作</p>
</li>
</ul>
<ol>
<li>demo2配置内网网卡网关为防火墙的内网ip，并配置DNS</li>
</ol>
<figure class="highlight shell"><table><tr><td class="gutter"><pre><span class="line">1</span><br><span class="line">2</span><br><span class="line">3</span><br><span class="line">4</span><br><span class="line">5</span><br></pre></td><td class="code"><pre><span class="line"><span class="meta prompt_"># </span><span class="language-bash">demo2</span></span><br><span class="line">vim /etc/sysconfig/network-scripts/ifcfg-ens33</span><br><span class="line">GATEWAY=192.168.10.10</span><br><span class="line">DNS1=114.114.114.114</span><br><span class="line">systemctl restart network		## 或者停止网卡再启动 ifdown ens34 &amp;&amp; ifup ens34</span><br></pre></td></tr></table></figure>

<ol start="2">
<li>demo1开启内核转发参数</li>
</ol>
<figure class="highlight shell"><table><tr><td class="gutter"><pre><span class="line">1</span><br><span class="line">2</span><br><span class="line">3</span><br><span class="line">4</span><br></pre></td><td class="code"><pre><span class="line">vim /etc/sysctl.conf</span><br><span class="line">net.ipv4.ip_forward=1</span><br><span class="line"><span class="meta prompt_"># </span><span class="language-bash">加载内核参数</span></span><br><span class="line">sysctl -p</span><br></pre></td></tr></table></figure>

<ol start="3">
<li><p>配置防火墙开启内网转发</p>
<blockquote>
<p>-o		指定流量包的出口设备网卡是外网网卡</p>
<p>-j SNAT	规则策略是将请求包的来源地址进行转换</p>
<p>–to-source		转换为的目标ip是多少</p>
</blockquote>
</li>
</ol>
<figure class="highlight shell"><table><tr><td class="gutter"><pre><span class="line">1</span><br><span class="line">2</span><br><span class="line">3</span><br></pre></td><td class="code"><pre><span class="line">iptables -t nat -A POSTROUTING -s 192.168.10.0/24 -o ens33 -j SNAT --to-source 10.0.0.31</span><br><span class="line"><span class="meta prompt_"># </span><span class="language-bash">或者写成以下亦可</span></span><br><span class="line">iptables -t nat -A POSTROUTING -s 192.168.10.0/24 -o ens33 -j MASQUERADE</span><br></pre></td></tr></table></figure>

<ol start="4">
<li>查看防火墙规则</li>
</ol>
<figure class="highlight shell"><table><tr><td class="gutter"><pre><span class="line">1</span><br></pre></td><td class="code"><pre><span class="line">iptables -t nat -nL</span><br></pre></td></tr></table></figure>

<ol start="5">
<li>demo2 访问百度测试</li>
</ol>
<figure class="highlight shell"><table><tr><td class="gutter"><pre><span class="line">1</span><br></pre></td><td class="code"><pre><span class="line">ping www.baidu.com</span><br></pre></td></tr></table></figure>

</article><div class="post-copyright"><div class="post-copyright__author"><span class="post-copyright-meta"><i class="fas fa-circle-user fa-fw"></i>文章作者: </span><span class="post-copyright-info"><a href="https://duolili.duolili.top">惰 立</a></span></div><div class="post-copyright__type"><span class="post-copyright-meta"><i class="fas fa-square-arrow-up-right fa-fw"></i>文章链接: </span><span class="post-copyright-info"><a href="https://duolili.duolili.top/2023/11/23/iptables/">https://duolili.duolili.top/2023/11/23/iptables/</a></span></div><div class="post-copyright__notice"><span class="post-copyright-meta"><i class="fas fa-circle-exclamation fa-fw"></i>版权声明: </span><span class="post-copyright-info">本博客所有文章除特别声明外，均采用 <a href="https://creativecommons.org/licenses/by-nc-sa/4.0/" target="_blank">CC BY-NC-SA 4.0</a> 许可协议。转载请注明来自 <a href="https://duolili.duolili.top" target="_blank">惰 立</a>！</span></div></div><div class="tag_share"><div class="post-meta__tag-list"><a class="post-meta__tags" href="/tags/Linux/">Linux</a><a class="post-meta__tags" href="/tags/%E8%BF%90%E7%BB%B4/">运维</a><a class="post-meta__tags" href="/tags/iptable/">iptable</a></div><div class="post_share"><div class="social-share" data-image="https://cdn.jsdelivr.net/gh/duoli-hub/cdn/source/img/cover/4.png" data-sites="facebook,twitter,wechat,weibo,qq"></div><link rel="stylesheet" href="https://cdn.jsdelivr.net/npm/butterfly-extsrc/sharejs/dist/css/share.min.css" media="print" onload="this.media='all'"><script src="https://cdn.jsdelivr.net/npm/butterfly-extsrc/sharejs/dist/js/social-share.min.js" defer></script></div></div><div class="post-reward"><div class="reward-button"><i class="fas fa-qrcode"></i>赞助</div><div class="reward-main"><ul class="reward-all"><li class="reward-item"><a href="/img/wechat.jpg" target="_blank"><img class="post-qr-code-img" src="/img/wechat.jpg" alt="wechat"/></a><div class="post-qr-code-desc">wechat</div></li><li class="reward-item"><a href="/img/alipay.jpg" target="_blank"><img class="post-qr-code-img" src="/img/alipay.jpg" alt="alipay"/></a><div class="post-qr-code-desc">alipay</div></li></ul></div></div><nav class="pagination-post" id="pagination"><div class="prev-post pull-left"><a href="/2023/11/23/%E6%97%B6%E9%97%B4%E6%9C%8D%E5%8A%A1%E5%99%A8/" title="时间服务器"><img class="cover" src="https://cdn.jsdelivr.net/gh/duoli-hub/cdn/source/img/cover/19.png" onerror="onerror=null;src='/img/404.jpg'" alt="cover of previous post"><div class="pagination-info"><div class="label">上一篇</div><div class="prev_info">时间服务器</div></div></a></div><div class="next-post pull-right"><a href="/2023/11/23/hello-world/" title="Hello World"><img class="cover" src="https://cdn.jsdelivr.net/gh/duoli-hub/cdn/source/img/cover/23.png" onerror="onerror=null;src='/img/404.jpg'" alt="cover of next post"><div class="pagination-info"><div class="label">下一篇</div><div class="next_info">Hello World</div></div></a></div></nav><div class="relatedPosts"><div class="headline"><i class="fas fa-thumbs-up fa-fw"></i><span>相关推荐</span></div><div class="relatedPosts-list"><div><a href="/2023/11/23/Ansible-Semaphore/" title="Ansible-Semaphore"><img class="cover" src="https://cdn.jsdelivr.net/gh/duoli-hub/cdn/source/img/cover/51.png" alt="cover"><div class="content is-center"><div class="date"><i class="far fa-calendar-alt fa-fw"></i> 2023-11-23</div><div class="title">Ansible-Semaphore</div></div></a></div><div><a href="/2023/11/23/JDK%E5%AE%89%E8%A3%85/" title="JDK安装"><img class="cover" src="https://cdn.jsdelivr.net/gh/duoli-hub/cdn/source/img/cover/42.png" alt="cover"><div class="content is-center"><div class="date"><i class="far fa-calendar-alt fa-fw"></i> 2023-11-23</div><div class="title">JDK安装</div></div></a></div><div><a href="/2023/11/23/SubVersion/" title="SubVersion"><img class="cover" src="https://jsd.012700.xyz/gh/jerryc127/CDN@latest/cover/default_bg3.png" alt="cover"><div class="content is-center"><div class="date"><i class="far fa-calendar-alt fa-fw"></i> 2023-11-23</div><div class="title">SubVersion</div></div></a></div><div><a href="/2023/11/23/%E6%97%B6%E9%97%B4%E6%9C%8D%E5%8A%A1%E5%99%A8/" title="时间服务器"><img class="cover" src="https://cdn.jsdelivr.net/gh/duoli-hub/cdn/source/img/cover/19.png" alt="cover"><div class="content is-center"><div class="date"><i class="far fa-calendar-alt fa-fw"></i> 2023-11-23</div><div class="title">时间服务器</div></div></a></div></div></div></div><div class="aside-content" id="aside-content"><div class="card-widget card-info"><div class="is-center"><div class="avatar-img"><img src="/img/tou.jpeg" onerror="this.onerror=null;this.src='/img/friend_404.gif'" alt="avatar"/></div><div class="author-info__name">惰 立</div><div class="author-info__description">惰尽这，焉有不立乎</div></div><div class="card-info-data site-data is-center"><a href="/archives/"><div class="headline">文章</div><div class="length-num">6</div></a><a href="/tags/"><div class="headline">标签</div><div class="length-num">7</div></a><a href="/categories/"><div class="headline">分类</div><div class="length-num">2</div></a></div><a id="card-info-btn" target="_blank" rel="noopener" href="https://github.com/xxxxxx"><i class="fab fa-github"></i><span>Follow Me</span></a><div class="card-info-social-icons is-center"><a class="social-icon" href="https://github.com/" target="_blank" title="Github"><i class="fab fa-github" style="color: #24292e;"></i></a></div></div><div class="card-widget card-announcement"><div class="item-headline"><i class="fas fa-bullhorn fa-shake"></i><span>公告</span></div><div class="announcement_content">This is my Blog</div></div><div class="sticky_layout"><div class="card-widget" id="card-toc"><div class="item-headline"><i class="fas fa-stream"></i><span>目录</span><span class="toc-percentage"></span></div><div class="toc-content"><ol class="toc"><li class="toc-item toc-level-2"><a class="toc-link" href="#%E5%9B%9B%E8%A1%A8%E4%BA%94%E9%93%BE"><span class="toc-number">1.</span> <span class="toc-text">四表五链</span></a></li><li class="toc-item toc-level-2"><a class="toc-link" href="#%E5%AE%89%E8%A3%85%E9%98%B2%E7%81%AB%E5%A2%99%E6%9C%8D%E5%8A%A1%E7%AB%AF"><span class="toc-number">2.</span> <span class="toc-text">安装防火墙服务端</span></a></li><li class="toc-item toc-level-2"><a class="toc-link" href="#%E5%90%AF%E5%8A%A8"><span class="toc-number">3.</span> <span class="toc-text">启动</span></a></li><li class="toc-item toc-level-2"><a class="toc-link" href="#%E6%9F%A5%E7%9C%8B%E8%A7%84%E5%88%99"><span class="toc-number">4.</span> <span class="toc-text">查看规则</span></a></li><li class="toc-item toc-level-2"><a class="toc-link" href="#%E9%98%B2%E7%81%AB%E5%A2%99%E5%88%9D%E5%A7%8B%E5%8C%96%E8%A7%84%E5%88%99"><span class="toc-number">5.</span> <span class="toc-text">防火墙初始化规则</span></a></li><li class="toc-item toc-level-2"><a class="toc-link" href="#%E6%9F%A5%E7%9C%8B%E9%98%B2%E7%81%AB%E5%A2%99%E8%A7%84%E5%88%99"><span class="toc-number">6.</span> <span class="toc-text">查看防火墙规则</span></a></li><li class="toc-item toc-level-2"><a class="toc-link" href="#%E5%9F%BA%E4%BA%8Efilter%E8%A1%A8%E8%A7%84%E5%88%99%E9%85%8D%E7%BD%AE"><span class="toc-number">7.</span> <span class="toc-text">基于filter表规则配置</span></a><ol class="toc-child"><li class="toc-item toc-level-3"><a class="toc-link" href="#%E5%AE%9A%E4%B9%89%E9%98%B2%E7%81%AB%E5%A2%99%E8%A7%84%E5%88%99%E9%A1%BA%E5%BA%8F"><span class="toc-number">7.1.</span> <span class="toc-text">定义防火墙规则顺序</span></a></li><li class="toc-item toc-level-3"><a class="toc-link" href="#%E5%9F%BA%E4%BA%8E%E7%8E%B0%E6%9C%89%E8%A7%84%E5%88%99%E5%8E%BB%E4%BF%AE%E6%94%B9"><span class="toc-number">7.2.</span> <span class="toc-text">基于现有规则去修改</span></a></li><li class="toc-item toc-level-3"><a class="toc-link" href="#%E5%90%8C%E6%97%B6%E6%94%BE%E8%A1%8C%E6%9F%90%E8%8C%83%E5%9B%B4%E5%86%85%E7%9A%84%E6%89%80%E6%9C%89%E7%AB%AF%E5%8F%A3"><span class="toc-number">7.3.</span> <span class="toc-text">同时放行某范围内的所有端口</span></a></li><li class="toc-item toc-level-3"><a class="toc-link" href="#%E6%8C%87%E5%AE%9A%E5%BC%80%E6%94%BE%E6%9F%90%E5%87%A0%E4%B8%AA%E7%AB%AF%E5%8F%A3"><span class="toc-number">7.4.</span> <span class="toc-text">指定开放某几个端口</span></a></li><li class="toc-item toc-level-3"><a class="toc-link" href="#%E7%A6%81%E7%94%A8ping"><span class="toc-number">7.5.</span> <span class="toc-text">禁用ping</span></a></li><li class="toc-item toc-level-3"><a class="toc-link" href="#%E9%99%90%E5%88%B6%E6%AF%8F%E5%88%86%E9%92%9F%E6%9C%80%E5%A4%9A%E5%8F%AF%E4%BB%A5ping6%E6%AC%A1%EF%BC%8C%E4%BB%8E%E7%AC%AC%E5%8D%81%E6%AC%A1%E5%BC%80%E5%A7%8B%E8%A7%A6%E5%8F%91"><span class="toc-number">7.6.</span> <span class="toc-text">限制每分钟最多可以ping6次，从第十次开始触发</span></a></li><li class="toc-item toc-level-3"><a class="toc-link" href="#%E5%88%A0%E9%99%A4%E8%A7%84%E5%88%99"><span class="toc-number">7.7.</span> <span class="toc-text">删除规则</span></a></li><li class="toc-item toc-level-3"><a class="toc-link" href="#%E4%BF%AE%E6%94%B9%E9%BB%98%E8%AE%A4%E8%A7%84%E5%88%99"><span class="toc-number">7.8.</span> <span class="toc-text">修改默认规则</span></a></li></ol></li><li class="toc-item toc-level-2"><a class="toc-link" href="#%E5%9F%BA%E4%BA%8Enat%E8%A1%A8%E8%A7%84%E5%88%99%E9%85%8D%E7%BD%AE"><span class="toc-number">8.</span> <span class="toc-text">基于nat表规则配置</span></a><ol class="toc-child"><li class="toc-item toc-level-3"><a class="toc-link" href="#NAT%E5%AE%9E%E7%8E%B0%E5%86%85%E9%83%A8%E7%BD%91%E7%BB%9C%E5%85%B1%E4%BA%AB%E4%B8%8A%E7%BD%91%E5%8A%9F%E8%83%BD"><span class="toc-number">8.1.</span> <span class="toc-text">NAT实现内部网络共享上网功能</span></a></li></ol></li></ol></div></div><div class="card-widget card-recent-post"><div class="item-headline"><i class="fas fa-history"></i><span>最新文章</span></div><div class="aside-list"><div class="aside-list-item"><a class="thumbnail" href="/2023/11/23/SubVersion/" title="SubVersion"><img src="https://jsd.012700.xyz/gh/jerryc127/CDN@latest/cover/default_bg3.png" onerror="this.onerror=null;this.src='/img/404.jpg'" alt="SubVersion"/></a><div class="content"><a class="title" href="/2023/11/23/SubVersion/" title="SubVersion">SubVersion</a><time datetime="2023-11-23T13:48:13.000Z" title="发表于 2023-11-23 21:48:13">2023-11-23</time></div></div><div class="aside-list-item"><a class="thumbnail" href="/2023/11/23/Ansible-Semaphore/" title="Ansible-Semaphore"><img src="https://cdn.jsdelivr.net/gh/duoli-hub/cdn/source/img/cover/51.png" onerror="this.onerror=null;this.src='/img/404.jpg'" alt="Ansible-Semaphore"/></a><div class="content"><a class="title" href="/2023/11/23/Ansible-Semaphore/" title="Ansible-Semaphore">Ansible-Semaphore</a><time datetime="2023-11-23T13:41:08.000Z" title="发表于 2023-11-23 21:41:08">2023-11-23</time></div></div><div class="aside-list-item"><a class="thumbnail" href="/2023/11/23/JDK%E5%AE%89%E8%A3%85/" title="JDK安装"><img src="https://cdn.jsdelivr.net/gh/duoli-hub/cdn/source/img/cover/42.png" onerror="this.onerror=null;this.src='/img/404.jpg'" alt="JDK安装"/></a><div class="content"><a class="title" href="/2023/11/23/JDK%E5%AE%89%E8%A3%85/" title="JDK安装">JDK安装</a><time datetime="2023-11-23T13:32:08.000Z" title="发表于 2023-11-23 21:32:08">2023-11-23</time></div></div><div class="aside-list-item"><a class="thumbnail" href="/2023/11/23/%E6%97%B6%E9%97%B4%E6%9C%8D%E5%8A%A1%E5%99%A8/" title="时间服务器"><img src="https://cdn.jsdelivr.net/gh/duoli-hub/cdn/source/img/cover/19.png" onerror="this.onerror=null;this.src='/img/404.jpg'" alt="时间服务器"/></a><div class="content"><a class="title" href="/2023/11/23/%E6%97%B6%E9%97%B4%E6%9C%8D%E5%8A%A1%E5%99%A8/" title="时间服务器">时间服务器</a><time datetime="2023-11-23T11:07:46.000Z" title="发表于 2023-11-23 19:07:46">2023-11-23</time></div></div><div class="aside-list-item"><a class="thumbnail" href="/2023/11/23/iptables/" title="iptables"><img src="https://cdn.jsdelivr.net/gh/duoli-hub/cdn/source/img/cover/4.png" onerror="this.onerror=null;this.src='/img/404.jpg'" alt="iptables"/></a><div class="content"><a class="title" href="/2023/11/23/iptables/" title="iptables">iptables</a><time datetime="2023-11-23T08:44:45.000Z" title="发表于 2023-11-23 16:44:45">2023-11-23</time></div></div></div></div></div></div></main><footer id="footer"><div id="footer-wrap"><div class="copyright">&copy;2023 By 惰 立</div><div class="framework-info"><span>框架 </span><a target="_blank" rel="noopener" href="https://hexo.io">Hexo</a><span class="footer-separator">|</span><span>主题 </span><a target="_blank" rel="noopener" href="https://github.com/jerryc127/hexo-theme-butterfly">Butterfly</a></div><div class="footer_custom_text">Hi, welcome to my <a target="_blank" rel="noopener" href="https://duolili.duolili.topg/">blog</a>!</div></div></footer></div><div id="rightside"><div id="rightside-config-hide"><button id="readmode" type="button" title="阅读模式"><i class="fas fa-book-open"></i></button><button id="darkmode" type="button" title="浅色和深色模式转换"><i class="fas fa-adjust"></i></button><button id="hide-aside-btn" type="button" title="单栏和双栏切换"><i class="fas fa-arrows-alt-h"></i></button></div><div id="rightside-config-show"><button id="rightside-config" type="button" title="设置"><i class="fas fa-cog fa-spin"></i></button><button class="close" id="mobile-toc-button" type="button" title="目录"><i class="fas fa-list-ul"></i></button><button id="go-up" type="button" title="回到顶部"><span class="scroll-percent"></span><i class="fas fa-arrow-up"></i></button></div></div><div><script src="/js/utils.js"></script><script src="/js/main.js"></script><script src="https://cdn.jsdelivr.net/npm/@fancyapps/ui/dist/fancybox/fancybox.umd.min.js"></script><script src="https://cdn.jsdelivr.net/npm/instant.page/instantpage.min.js" type="module"></script><script>function panguFn () {
  if (typeof pangu === 'object') pangu.autoSpacingPage()
  else {
    getScript('https://cdn.jsdelivr.net/npm/pangu/dist/browser/pangu.min.js')
      .then(() => {
        pangu.autoSpacingPage()
      })
  }
}

function panguInit () {
  if (false){
    GLOBAL_CONFIG_SITE.isPost && panguFn()
  } else {
    panguFn()
  }
}

document.addEventListener('DOMContentLoaded', panguInit)</script><div class="js-pjax"></div><script defer="defer" id="fluttering_ribbon" mobile="true" src="https://cdn.jsdelivr.net/npm/butterfly-extsrc/dist/canvas-fluttering-ribbon.min.js"></script><script id="canvas_nest" defer="defer" color="0,0,255" opacity="0.7" zIndex="-1" count="99" mobile="true" src="https://cdn.jsdelivr.net/npm/butterfly-extsrc/dist/canvas-nest.min.js"></script><script async data-pjax src="//busuanzi.ibruce.info/busuanzi/2.3/busuanzi.pure.mini.js"></script></div></body></html>